Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6849 | Jenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. |
Github GHSA |
GHSA-j7xv-fc46-hgpg | Jenkins BigPanda Notifier Plugin stores BigPanda API key unencrypted |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 27 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-05-27T18:24:13.463Z
Reserved: 2022-09-21T00:00:00.000Z
Link: CVE-2022-41247
Updated: 2024-08-03T12:35:49.567Z
Status : Modified
Published: 2022-09-21T16:15:11.213
Modified: 2025-05-27T19:15:23.903
Link: CVE-2022-41247
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA